Report - 7501.ps1

Generic Malware Antivirus
ScreenShot
Created 2021.08.26 08:49 Machine s1_win7_x6402
Filename 7501.ps1
Type awk or perl script, ASCII text, with very long lines, with CRLF line terminators
AI Score Not founds Behavior Score
4.4
ZERO API file : clean
VT API (file) 3 detected (PowerShell)
md5 5480fceef4e5290938cb0a23955358df
sha256 d9cfdea62d4a3acc5ec47cfc0349002af129add61611a0810b73394bc7ea3020
ssdeep 96:DTDsM8M25rkuqCNshBU+iA99IBNXQMnVJQ8t6W1MG1MGtMTtxFsrkOO60WPEG0uJ:H32VkDhBU+iAbIBNJnVJQ8tzeGeG2TPA
imphash
impfuzzy
  Network IP location

Signature (10cnts)

Level Description
watch Executes one or more WMI queries
watch Installs itself for autorun at Windows startup
watch Network communications indicative of a potential document or script payload download was initiated by the process powershell.exe
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates executable files on the filesystem
notice Executes one or more WMI queries which can be used to identify virtual machines
notice File has been identified by 3 AntiVirus engines on VirusTotal as malicious
notice Poweshell is sending data to a remote host
notice URL downloaded by powershell script
info Queries for the computername

Rules (3cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (download)
watch Antivirus Contains references to security software binaries (download)
watch Antivirus Contains references to security software binaries (upload)

Network (3cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://serv01.nerdpol.ovh:7501/Vre FR Inulogic Sarl 185.81.157.187 clean
serv01.nerdpol.ovh FR Inulogic Sarl 185.81.157.187 clean
185.81.157.187 FR Inulogic Sarl 185.81.157.187 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure